Threat Advisory

Void Rabisu Targets Female Political Leaders with New Slimmed-Down ROMCOM Variant

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Void Rabisu, a threat actor known for both financially motivated ransomware attacks and targeted campaigns, has continued its evolution by enhancing its primary malware, the ROMCOM backdoor. Researcher explores recent activities, with a focus on a campaign that exploited the Women Political Leaders (WPL) Summit in Brussels in August 2023. Void Rabisu's tactics reflect a blend of approaches typically associated with cybercriminals and those attributed to nation-state-sponsored actors.[/subscribe_to_unlock_form]

Summary:

Void Rabisu, a threat actor known for both financially motivated ransomware attacks and targeted campaigns, has continued its evolution by enhancing its primary malware, the ROMCOM backdoor. Researcher explores recent activities, with a focus on a campaign that exploited the Women Political Leaders (WPL) Summit in Brussels in August 2023. Void Rabisu's tactics reflect a blend of approaches typically associated with cybercriminals and those attributed to nation-state-sponsored actors.[emaillocker id="1283"]

The threat actors distributed malware disguised as event photographs. While victims were distracted by these images, the malware-initiated communication with a command-and-control (C&C) server. The malware payload was delivered in stages, with a dynamically loaded DLL running in memory. This DLL interacted with C&C servers using advanced techniques, including the use of TLS 1.2 and the deliberate disregard of certificate errors to maintain operational security.

Researcher also underscores the shift from ROMCOM 3.0 to the newer PEAPOD malware. PEAPOD differs from its predecessor in several key aspects. While ROMCOM 3.0 used a modified installation program for component distribution, PEAPOD relies on an executable (EXE) for downloading an XOR-encrypted DLL, facilitating the retrieval of other components. Both malware variants share a modular structure, with components such as a COM hijacking loader and network-related modules. However, PEAPOD introduces changes in inter-process communication (IPC), incorporating named pipes rather than local sockets. Additionally, it supports a reduced set of commands compared to ROMCOM 3.0, which might indicate a more focused approach.

Void Rabisu's transition from ransomware to espionage is apparent in its continuous development of the ROMCOM backdoor. By simplifying the backdoor and dynamically downloading additional components, Void Rabisu gains versatility and reduces its exposure to security researchers. While Void Rabisu's affiliation with nation-state sponsorship remains uncertain, its persistent focus on targeted conferences and interest groups suggests a proactive engagement in espionage. Continuous monitoring of their evolving tactics and campaigns is vital to understanding the ever-changing cyber threat landscape.

Threat Profile:

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/women-political-leaders-summit-targeted-in-romcom-malware-phishing/

[/emaillocker]
crossmenu